← All posts

Eight Hours. Six Days. 3.7 Million People.

On Tuesday, the Department of Health and Human Services breach portal updated a single line item. CareCloud, a New Jersey health technology company that provides electronic health records and billing systems to more than 45,000 medical providers, now reports that 3,756,469 people had their information stolen in a breach that happened in March.

Five months ago, the same company told the Securities and Exchange Commission the incident lasted about eight hours.

Both statements can be true. That is exactly the problem — and it is the most useful thing on any board agenda this week.

What the March filing said

CareCloud filed a Form 8-K under Item 1.05 — the mandatory track, reserved for incidents a company has determined to be material — on March 27. The filing is careful, specific, and reads like a company that handled things well.

It describes a "temporary network disruption" on March 16 that partially affected one of the company's six electronic health record environments "for approximately 8 hours until the Company fully restored all functionality and data access during that evening." It says the incident "was contained on the day it was discovered." It says the company engaged a Big Four cyber response team, notified law enforcement, and believed the threat actor "no longer has any access."

Then the sentence that matters most: the company "continues to assess whether, and the extent to which, patient information or other data was accessed or exfiltrated, and the categories and volume of any such data."

Read that again. On March 27, CareCloud told the market the disruption was eight hours and contained — while stating plainly that it did not yet know what had been taken.

What the notifications said in July

By late July, breach notification letters filed with state attorneys general told a different-shaped story. Reporting from The Record and SecurityWeek, both citing those filings, described unauthorized access to one of CareCloud's Amazon Web Services environments running from March 10 to March 16 — six days, not eight hours. The attacker exfiltrated data. The stolen categories include names, addresses, Social Security numbers, driver's license numbers, dates of birth, health insurance details, and medical records, plus full payment card data for a small subset of people.

The notification letter CareCloud filed with Massachusetts regulators puts a date on the turn: June 24 — the day the investigation determined that personal, financial, and medical information had in fact been compromised. Three months after the eight-hour disruption.

Those July state filings added up to roughly 350,000 individuals.

Then Monday's HHS filing said 3,371,508. Tuesday's said 3,756,469. SecurityWeek asked HHS whether the ten-fold jump was a clerical error; HHS confirmed the figure is accurate.

Nothing here proves anyone misled anyone. The eight hours described a service disruption. The six days described attacker dwell time in a cloud environment — a fact forensics surfaces later, because it has to be reconstructed from logs. The 350,000 was what had been confirmed in July. The 3.7 million is what was confirmed in August.

That is the normal metabolism of a real incident. And it is why the first number a company publishes should never be the number a board plans around.

The gap between disclosure and truth

I write about this pattern in Cyber Risk Is Business Risk because it burns executives more reliably than any technical failure. Regulatory clocks and forensic clocks run at different speeds, and they are not designed to agree.

The SEC gives you four business days from a materiality determination. HIPAA gives covered entities and their business associates up to 60 days from discovery to notify. Forensic reconstruction of a cloud environment can take months, and it routinely revises both the dwell time and the record count upward.

So the disclosure your company makes first is, by construction, the least-informed statement it will ever make about the incident — and it is the one that gets quoted for the next two years.

For the roughly 45,000 provider organizations that use CareCloud, there is a second lesson layered on top. Their patients are in that 3.7 million. Their names are on the relationship. CareCloud filed the breach report, but a patient who gets a letter does not think about business associate agreements — they think about the doctor's office that gave away their Social Security number. You can outsource the storage. You cannot outsource whose name is on the harm.

The Three Questions, applied

What is our actual exposure? Not "did our vendor have a breach," but: which vendors hold our customers' most sensitive data, in whose cloud, and what would the notification letter say if that data walked out tomorrow? Most boards cannot answer this in the room. Ask anyway — the inability to answer is the answer.

Who owns the number, and how does it get revised? Someone in your company will publish a first count. Name that person now. Then ask what process exists to update the count publicly when forensics moves it, and who has authority to pull that trigger.

What happens to us if a vendor's number moves? CareCloud's revision from 350,000 to 3.7 million landed on 45,000 provider organizations that had no control over the timing or the message. If your third-party contracts do not give you notification rights, data-scope reporting, and a say in customer communications, you are a passenger.

What to ask your CISO this week

Three questions, and none of them are technical.

First: for our top ten vendors by data sensitivity, do we know what data they hold and where it physically lives? Not the contract summary — the actual answer.

Second: if we had to publish a breach count in four business days, what would our process be for saying "this number will likely change," and would legal let us say it?

Third: when a vendor discloses a breach that touches our customers, who at our company writes to those customers, and how fast? If the answer involves a committee that has never met, you have found this quarter's most important gap.

One last note on how to read stories like this one. TechCrunch reports that CareCloud's chief executive has not responded to repeated questions about the incident, including who at the company is responsible for cybersecurity. Silence from the top is not proof of misconduct. But it is a governance signal, and boards should read it as one — because regulators, plaintiffs' lawyers, and customers certainly will.